Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 343

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
The two 'HALO' stocks that haven't left Josh Brown's list since being added earlier this year
Jim Cramer says these 2 cybersecurity stocks can keep climbing as AI threats grow
Cramer's advice on Apple after analyst upgrade. Plus, why 2 chipmakers are up big
Hayden Panettiere, who starred in ‘Heroes’ and ‘Nashville,’ dies at 36
Russia targets Danube port after one of Ukraine’s largest aerial attacks of the war
OpenAI's Brockman brushes off concerns about leadership changes in CNBC exclusive
What Pavement song is this?
Movie: Normal
Movie: New York, New York
Nvidia backing $105 billion in financing for OpenAI data center in Ohio